CVE-2024-26975

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
01/05/2024
Last modified:
23/12/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> powercap: intel_rapl: Fix a NULL pointer dereference<br /> <br /> A NULL pointer dereference is triggered when probing the MMIO RAPL<br /> driver on platforms with CPU ID not listed in intel_rapl_common CPU<br /> model list.<br /> <br /> This is because the intel_rapl_common module still probes on such<br /> platforms even if &amp;#39;defaults_msr&amp;#39; is not set after commit 1488ac990ac8<br /> ("powercap: intel_rapl: Allow probing without CPUID match"). Thus the<br /> MMIO RAPL rp-&gt;priv-&gt;defaults is NULL when registering to RAPL framework.<br /> <br /> Fix the problem by adding sanity check to ensure rp-&gt;priv-&gt;rapl_defaults<br /> is always valid.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.5 (including) 6.6.24 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.7.12 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.8 (including) 6.8.3 (excluding)